Platform layer — Trust & Credentials
Managed credential issuers.
Certified Participant Credential Issuer (PR v3) and Authorization Registry. The trust core of every Protium managed service. iSHARE v3 certified, 100% Protium IP on the issuing logic.
Participant Credential Issuer (PR v3)
The certified issuer of participant identity credentials inside the iSHARE trust framework. Establishes "who you are" for every actor — people, systems and AI agents — that participates in a data ecosystem.
Authorization Registry
The certified record of data rights. Establishes "what you are allowed" for every actor. Together with the PR Issuer, this is the trust core that gives data exchange the documented terms and evidence the EU Data Act expects.
What sets the issuer apart
The full iSHARE v3 credential vocabulary
Not just the participant credential: dataspace agreements, memberships, roles, framework compliance, IdP assertions and X.509 certificate credentials — each mapped to the official schemas.ishare.eu/v3 schema index.
Both issuance protocols, per call
OpenID4VCI and DCP are both supported and selectable per issuance. Most credential vendors implement one; data spaces increasingly require both.
Participation without running a wallet
Custodial wallet mode lets an organisation join a data space before it operates its own wallet — credentials anchored to one organisational identity, upgradeable to self-managed later.
Governed operator access
Issuer administration runs under named roles — admin, operator, assessor, auditor — behind enterprise SSO, with passkey (WebAuthn) login available. Separation of duties is built into the product, not into a procedure document.
IP position — transparent and verifiable
The PR v3 Issuer logic and workflows are 100% Protium IP. The Authorization Registry is 100% Protium IP. The PR base code comes from iSHARE Foundation as open source under AGPL 3.0 — freely deployable, no commercial restriction.
| Component | IP position |
|---|---|
| PR base code | iSHARE Foundation open source under AGPL 3.0. |
| PR v3 Issuer logic | 100% Protium IP. |
| Authorization Registry | 100% Protium IP. |
| Ozone platform | Proprietary Protium IP. |
Standards compliance
W3C Verifiable Credentials
The open credential model at the core of the stack.
OID4VCI
OpenID for Verifiable Credential Issuance.
DCP
Decentralized Claims Protocol — issuance and presentation for data-space participants.
SD-JWT
Privacy-preserving, selectively disclosable credentials.
EUDI Wallet ARF
Aligned with the European Digital Identity Wallet reference architecture.
iSHARE v3
European trust framework for data spaces — Protium is certified on two roles.
MCP-compatible
Authorization layer for the Model Context Protocol ecosystem.
EU Data Act
Applies since 12 September 2025 — our stack makes its data-access obligations operational.
Integration patterns
For telco wholesale operators
Issuer and registry deployed in your sovereign cloud. Tenant-isolated per enterprise customer. Telemetry per tenant. Full white-label.
For enterprises
Issuer and registry as a managed service. Integrates with your IAM. Credentials for AI agents, partners and customer portals.
For data spaces
Issuer and registry as the trust core of a sector ecosystem. Operated under the data space governance you and Protium agree.